summaryrefslogtreecommitdiff
path: root/internal/controlplane/access_test.go
diff options
context:
space:
mode:
authorChia <Chia@93.nz>2026-08-06 09:29:41 +1200
committerChia <Chia@93.nz>2026-08-06 09:32:46 +1200
commit41e322c53d7b4b796eb377d0df9c29ecd10ba431 (patch)
treec730526150e55e39b822d5197e4a20318ecaa449 /internal/controlplane/access_test.go
parenteadb2ffe85c43cf6fc741c9823cd28eedb4a844c (diff)
feat: complete commercial control plane, billing, auth, and model catalog
- add PostgreSQL control-plane persistence with Redis-degraded hot reload - implement prepaid balance, usage ledger, Stripe top-up and reconciliation - add registration, email verification, password reset, invitations and RBAC - support TOTP, Passkey MFA, device sessions, quotas and rate limits - add tenant billing profiles, audit logs and operational readiness checks - build authenticated admin console, Quickstart, Playground and usage analytics - add public model catalog with pricing, filtering and cost estimation - support OpenAI Responses providers and provider health failover - validate real upstream usage reporting and balance settlement
Diffstat (limited to 'internal/controlplane/access_test.go')
-rw-r--r--internal/controlplane/access_test.go4
1 files changed, 4 insertions, 0 deletions
diff --git a/internal/controlplane/access_test.go b/internal/controlplane/access_test.go
index 7767e0d..d871024 100644
--- a/internal/controlplane/access_test.go
+++ b/internal/controlplane/access_test.go
@@ -13,8 +13,12 @@ func TestConsoleRolePermissions(t *testing.T) {
{RoleTenantAdmin, "keys.write", true},
{RoleTenantAdmin, "limits.write", true},
{RoleTenantBilling, "billing.topup", true},
+ {RoleTenantBilling, "billing.preferences.write", true},
+ {RoleTenantBilling, "developer.preferences.write", false},
{RoleTenantBilling, "keys.read", false},
{RoleTenantDeveloper, "keys.write", true},
+ {RoleTenantDeveloper, "developer.preferences.write", true},
+ {RoleTenantDeveloper, "billing.preferences.write", false},
{RoleTenantDeveloper, "billing.read", false},
{RoleTenantViewer, "usage.read", true},
{RoleTenantViewer, "users.read", false},